DBA AML · Legal

Privacy Policy.

Effective 3 August 2026 · DBA AML Group Pty Ltd · Australian Privacy Principles · Governed by the laws of New South Wales

01Who we are and what this policy covers

DBA AML Group Pty Ltd (ABN [ABN]) (DBA AML, we, us), a division of DBA Advisory, provides a regulatory client onboarding, compliance and lifecycle management platform (the Platform) and related compliance services, including outsourced AML/CTF compliance officer services, to Australian businesses regulated under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act).

This Privacy Policy explains how we collect, hold, use and disclose personal information, and how you can access and correct it or make a complaint. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and we take those obligations seriously — privacy discipline is, after all, our trade.

This policy covers our website (dbaaml.com), the Platform (including its authentication service at auth.dbaaml.com), and our compliance services.

02The two capacities in which we handle information

Understanding this policy starts with a distinction:

03What we collect

Account and contact information

Compliance-file information (processed for subscribers)

Technical and usage information

04Biometric and identity-verification information

Electronic identity verification on the Platform can include document checks, facial matching and liveness detection. Biometric information is sensitive information under the Privacy Act, and we treat it accordingly:

05Why we collect it and the lawful bases

PurposeBasis
Providing, securing and supporting the Platform and our servicesPerformance of our agreement with the subscriber
Enabling subscribers to meet customer identification, verification, screening, record-keeping and reporting obligationsThe subscriber’s legal obligations under the AML/CTF Act and Rules
Biometric identity verificationConsent of the individual, obtained at the point of verification
Billing, account administration and communicationsPerformance of our agreement; legitimate operation of our business
Complying with our own legal obligations, including to regulatorsRequired or authorised by law
Improving the Platform (on de-identified or aggregated information wherever practicable)Legitimate operation of our business

We do not sell personal information. We do not use client-file information for advertising, and we do not use biometric information to train models.

06Who we disclose information to

We disclose personal information only as needed to run the Platform and our services, on a need-to-know basis and under contractual confidentiality:

07Overseas disclosures

Some of our service providers (including cloud infrastructure, verification, screening and authentication providers) may store or process information outside Australia, including in the United States and other jurisdictions in which they operate. Where that occurs, we take reasonable steps — including contractual measures — to ensure the information is handled consistently with the APPs. Compliance records created on the Platform are retained under Australian law regardless of where the underlying infrastructure sits.

08How long we keep information

Retention on this Platform is largely dictated by statute. The AML/CTF Act requires reporting entities to retain customer identification and transaction records for seven years (generally from the end of the customer relationship or the making of the record). Records created on the Platform for a subscriber’s compliance program are therefore retained for at least that period, even after a client relationship or a subscription ends, unless the subscriber lawfully takes custody of them.

Information not subject to statutory retention (for example, marketing enquiries) is kept only as long as needed for the purpose it was collected, then deleted or de-identified.

09Legal limits on what we can tell you

An honest limitation: the AML/CTF Act prohibits “tipping off” — disclosing that a suspicious matter report has been made or may be made, or information from which that could be inferred. If a request for access to information would breach that prohibition or another law, we (and our subscribers) must refuse it to that extent, and may be unable to tell you why. Access requests are otherwise handled as section 10 describes.

10How we protect information

If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme.

11Access, correction and your choices

You may request access to, or correction of, personal information we hold about you by contacting us (section 13). We respond within a reasonable period, verify your identity before acting, and if we refuse a request (for example, where the law requires it — see section 8) we will tell you why to the extent we lawfully can, and how to complain.

If your information sits in a subscriber’s compliance file, we will refer your request to that subscriber, whose obligations and instructions govern that file. You can also opt out of any non-essential communications at any time; service and security notices are part of operating the Platform and cannot be opted out of while you hold an account.

12Cookies and website analytics

The website and Platform use cookies that are necessary for sign-in, security and session integrity. These are essential and cannot be disabled while using the Platform. Any analytics we use on the public website are configured for aggregate understanding of usage, not the profiling of individuals. You can control cookies through your browser; blocking essential cookies will prevent sign-in.

13Complaints

If you believe we have mishandled your personal information, contact us first (section 13) — we will acknowledge your complaint promptly, investigate, and respond within 30 days. If you are not satisfied with our response, you may complain to the OAIC at oaic.gov.au or 1300 363 992.

14Contacting us and changes to this policy

Privacy Officer
DBA AML Group Pty Ltd (a division of DBA Advisory)
Email: privacy@dbaaml.com
Address: G01/38A Cumberland St, The Rocks NSW 2000

We may update this policy from time to time. The current version is always at dbaaml.com/privacy.html, with its effective date shown at the top. Material changes affecting subscribers will be notified through the Platform.